Beveiligingsadvies

CVE-2026-9232

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-19 07:43:16
Laatst bijgewerkt 2026-09-19 14:01:23
Toegewezen door Wordfence
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.